Thinpro
Vendor:
First CVE: Dec 29, 2016 · Active for 9 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Thinpro over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 29, 2016
9 years ago
Most Recent CVE
Oct 28, 2025
269 days ago
CVE Severity & Scoring
Thinpro8 CVEs
38%
50%
13%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (37.5%)
Network2 (25.0%)
Unknown0 (0.0%)
Physical2 (25.0%)
Adjacent Network1 (12.5%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (50.0%)
High0 (0.0%)
None4 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-43017CRITICAL HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities. | Oct 28, 2025 | 9.8 | 30 | NO | NO |
CVE-2019-18909HIGH The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges. | Nov 22, 2019 | 8.0 | 26 | NO | NO |
CVE-2016-2246HIGH HP ThinPro 4.4 through 6.1 mishandles the keyboard layout control panel and virtual keyboard application, which allows local users to bypass intended access restrictions and gain p | Dec 29, 2016 | 7.8 | 26 | NO | NO |
CVE-2019-18910MEDIUM The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileg | Nov 22, 2019 | 6.8 | 23 | NO | NO |
CVE-2017-2740HIGH A potential security vulnerability has been identified with the command line shell of the HP ThinPro operating system 6.1, 5.2.1, 5.2, 5.1, 5.0, and 4.4. The vulnerability could re | Jan 23, 2018 | 7.8 | 23 | NO | NO |
CVE-2025-43024HIGH A GUI dialog of an application allows to view what files are in the file system without proper authorization. | Oct 28, 2025 | 7.5 | 22 | NO | NO |
CVE-2019-16287MEDIUM In HP ThinPro Linux 6.2, 6.2.1, 7.0 and 7.1, an attacker may be able to leverage the application filter bypass vulnerability to gain privileged access to create a file on the local | Nov 22, 2019 | 6.8 | 22 | NO | NO |
CVE-2022-1602MEDIUM A potential security vulnerability has been identified in HP ThinPro 7.2 Service Pack 8 (SP8). The security vulnerability in SP8 is not remedied after upgrading from SP8 to Service | Sep 13, 2022 | 5.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Thinpro
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.1 | 2 | 8.7 | 0.3% | 0 | 0 |
| 7.2 | 1 | 5.5 | 0.2% | 0 | 0 |
| 7.1 | 3 | 7.2 | 1.2% | 0 | 0 |
| 7.0 | 3 | 7.2 | 1.2% | 0 | 0 |
| 6.2.1 | 3 | 7.2 | 1.2% | 0 | 0 |
| 6.2 | 3 | 7.2 | 1.2% | 0 | 0 |
| 6.1 | 2 | 7.8 | 0.5% | 0 | 0 |
| 6.0 | 1 | 7.8 | 0.6% | 0 | 0 |
| 5.2.1 | 2 | 7.8 | 0.5% | 0 | 0 |
| 5.2 | 2 | 7.8 | 0.5% | 0 | 0 |
| 5.1 | 2 | 7.8 | 0.5% | 0 | 0 |
| 5.0 | 2 | 7.8 | 0.5% | 0 | 0 |
| 4.4 | 2 | 7.8 | 0.5% | 0 | 0 |